• Open Source Software Security Principles and Practices

    From Cisa Advisories@2:263/1 to All on Thu Jul 30 16:04:14 2026
    Open Source Software: Security Principles and Practices

    Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems.
    Visit CISA?s Open Source Security webpage for more resources. CISA is committed to providing access to our web pages and documents for
    individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email opensource@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material.



    Please share your thoughts!



    We welcome your feedback.



    CISA Product Survey

    https://www.cisa.gov/resources-tools/resources/open-source-software-security-pr inciples-and-practices

    2026-07-30 12:00 UTC

    --- BBBS/LiR v4.10 Toy-7
    * Origin: LISTS. from TCOB1 READ ONLY (2:263/1)